COPPA

COPPA: When a Service Is Child-Directed and What Follows

August 12, 2026

COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.

Read more →
GDPR

When the GDPR Reaches a US Company, and What It Requires Once It Does

August 12, 2026

The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.

Read more →
HIPAA

HIPAA in Practice: The Privacy, Security and Breach Notification Rules

August 12, 2026

HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.

Read more →
HIPAA

The HIPAA Security Rule Requirement That OCR Cites Most Often

August 12, 2026

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.

Read more →
BIPA

Illinois BIPA: What the Biometric Information Privacy Act Requires

August 12, 2026

Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.

Read more →
TCPA

TCPA Consent: What Is Required Before a Call or Text

August 12, 2026

The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.

Read more →
VPPA

How a 1988 Video Rental Statute Became a Website Tracking Problem

August 12, 2026

The Video Privacy Protection Act was passed in 1988 after a newspaper published a Supreme Court nominee's video rental history. It now generates a steady stream of claims against websites that embed video and third-party tracking pixels. Two questions divide the courts: who counts as a subscriber, and what qualifies as personally identifiable information.

Read more →
Consumer Health Data

Washington's My Health My Data Act Covers Health Data HIPAA Does Not

August 12, 2026

Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.

Read more →